Electronic Control Apparatus Anomaly Detection via Transmission State Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network monitoring techniques, such as those described in Patent Literature 1, are inadequate for detecting anomalies in data transmission as they rely on identifying anomalies based on message transmission cycles, which may not accurately detect spoofing when the transmission period appears normal or when authorized data is suppressed.
Innovation Solution
An electronic control apparatus and method that monitor network data by determining the transmission state of data, judging for anomalies when the transmission state is stopped, and managing transmission states for each information processor to improve detection accuracy, including using a storage unit to associate information processors with their transmission states and determining states based on instructions and output cycles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If anomaly detection is based on transmission cycle changes, then detection is possible when transmission cycles are altered, but detection fails when transmission period appears normal or authorized data is suppressed
Solution Approach 1:
The patent segments the anomaly detection process into multiple independent monitoring dimensions: transmission cycle monitoring, data content monitoring, and authorized data suppression detection. Each dimension operates independently to detect specific types of anomalies, allowing the system to cover multiple attack vectors without relying on a single detection method.
Solution Approach 2:
The patent adds new detection dimensions beyond transmission cycle analysis. Specifically, it introduces data content verification and authorized data suppression detection as additional dimensions. This multi-dimensional approach enables the system to detect anomalies that maintain normal transmission cycles, such as camouflage data attacks where spoofed data replaces authorized data with identical timing.
2Device complexity
If monitoring focuses on transmission cycle anomalies, then the monitoring system remains simple, but it cannot detect spoofing when transmission period is normal
Solution Approach 1:
The patent implements preliminary registration of authorized data characteristics, including transmission cycles and data content, before monitoring begins. This preliminary action establishes a baseline for comparison, enabling the system to detect deviations without requiring complex real-time analysis. The registered authorized data serves as a reference for identifying spoofing attempts.
Solution Approach 2:
The patent employs feedback mechanisms where detected anomalies trigger further verification steps. When an anomaly is detected in one dimension (e.g., transmission cycle), the system cross-checks with other dimensions (e.g., data content, authorized data presence) to confirm spoofing. This feedback loop improves reliability without proportionally increasing system complexity.
Data Source
AI summary
An electronic control apparatus includes: an obtaining unit configured to obtain data transmitted via a network in a system; and a judging unit configured to judge presence or absence of an anomaly in the data obtained by the obtaining unit, based on a transmission state of the data. The judging unit is configured to judge that an anomaly is present in the data, when the transmission state of the data is a transmission stopped state.


